{"api_version":"1","generated_at":"2026-07-23T22:42:23+00:00","cve":"CVE-2016-6548","urls":{"html":"https://cve.report/CVE-2016-6548","api":"https://cve.report/api/cve/CVE-2016-6548.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-6548","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-6548"},"summary":{"title":"CVE-2016-6548","description":"The Zizai Tech Nut mobile app makes requests via HTTP instead of HTTPS. These requests contain the user's authenticated session token with the URL. An attacker can capture these requests and reuse the session token to gain full access the user's account.","state":"PUBLIC","assigner":"cert@cert.org","published_at":"2018-07-13 20:29:00","updated_at":"2019-10-09 23:19:00"},"problem_types":["CWE-200"],"metrics":[],"references":[{"url":"https://www.securityfocus.com/bid/93877","name":"93877","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Zizai Tech Nut Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://blog.rapid7.com/2016/10/25/multiple-bluetooth-low-energy-ble-tracker-vulnerabilities/","name":"https://blog.rapid7.com/2016/10/25/multiple-bluetooth-low-energy-ble-tracker-vulnerabilities/","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Multiple Bluetooth Low Energy (BLE) Tracker Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.kb.cert.org/vuls/id/402847","name":"VU#402847","refsource":"CERT-VN","tags":["Third Party Advisory","US Government Resource"],"title":"Vulnerability Note VU#402847 - Zizai Tech Nut contains multiple vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-6548","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-6548","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Thanks to Deral Heiland and Adam Compton of Rapid7, Inc. for reporting this vulnerability.","lang":""}],"nvd_cpes":[{"cve_year":"2016","cve_id":"6548","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nutspace","cpe5":"nut_mobile","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"6548","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nutspace","cpe5":"nut_mobile","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cert@cert.org","ID":"CVE-2016-6548","STATE":"PUBLIC","TITLE":"Zizai Tech Nut mobile application makes requests using HTTP, which includes the users session token"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Tech Nut Mobile Application","version":{"version_data":[{"affected":"?","version_value":"N/A"}]}}]},"vendor_name":"Zizai Technology"}]}},"credit":[{"lang":"eng","value":"Thanks to Deral Heiland and Adam Compton of Rapid7, Inc. for reporting this vulnerability."}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Zizai Tech Nut mobile app makes requests via HTTP instead of HTTPS. These requests contain the user's authenticated session token with the URL. An attacker can capture these requests and reuse the session token to gain full access the user's account."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-200: Information Exposure"}]}]},"references":{"reference_data":[{"name":"93877","refsource":"BID","url":"https://www.securityfocus.com/bid/93877"},{"name":"https://blog.rapid7.com/2016/10/25/multiple-bluetooth-low-energy-ble-tracker-vulnerabilities/","refsource":"MISC","url":"https://blog.rapid7.com/2016/10/25/multiple-bluetooth-low-energy-ble-tracker-vulnerabilities/"},{"name":"VU#402847","refsource":"CERT-VN","url":"https://www.kb.cert.org/vuls/id/402847"}]},"source":{"discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2018-07-13 20:29:00","lastModifiedDate":"2019-10-09 23:19:00","problem_types":["CWE-200"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:nutspace:nut_mobile:-:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"6548","Ordinal":"92850","Title":"CVE-2016-6548","CVE":"CVE-2016-6548","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"6548","Ordinal":"1","NoteData":"The Zizai Tech Nut mobile app makes requests via HTTP instead of HTTPS. These requests contain the user's authenticated session token with the URL. An attacker can capture these requests and reuse the session token to gain full access the user's account.","Type":"Description","Title":null},{"CveYear":"2016","CveId":"6548","Ordinal":"2","NoteData":"2018-07-13","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"6548","Ordinal":"3","NoteData":"2018-07-13","Type":"Other","Title":"Modified"}]}}}